CVE-2026-16592: Unknown Wp Directory Kit
Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.
Affected products
- Unknown Wp Directory Kit: up to and including 1.5.7
Published 2026-09-15. Last modified 2026-09-16.